Vulnerability index

Browse CVEs

2,592 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Enterprise Linux Desktop HIGH 7.8
CVE-2018-15982 KEVEPSS 82%

Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability. Successful exploitation could lead to a…

Fix: after 31.0.0.153
Fix from $1,950 2019-01-18
Enterprise Linux Desktop HIGH 7.5
CVE-2018-5740EPSS 60%

"deny-answer-aliases" is a little-used feature intended to help recursive server operators protect end users against DNS rebinding attacks, a potenti…

Fix: 9.8.8 / 9.9.13+
Fix from $1,950 2019-01-16
Enterprise Linux Desktop HIGH 7.5
CVE-2017-3137EPSS 9%

Mistaken assumptions about the ordering of records in the answer section of a response containing CNAME or DNAME resource records could lead to a sit…

Mitigation only
Fix from $1,950 2019-01-16
Enterprise Linux Desktop HIGH 7.5
CVE-2017-3144EPSS 73%

A vulnerability stemming from failure to properly clean up closed OMAPI connections can lead to exhaustion of the pool of socket descriptors availabl…

Mitigation only
Fix from $1,950 2019-01-16
Enterprise Linux Desktop HIGH 7.5
CVE-2017-3145EPSS 28%

BIND was improperly sequencing cleanup operations on upstream recursion fetch contexts, leading in some cases to a use-after-free error that can trig…

Fix: after 9.11.2
Fix from $1,950 2019-01-16
Enterprise Linux Desktop HIGH 7.5
CVE-2018-5733EPSS 20%

A malicious client which is allowed to send very large amounts of traffic (billions of packets) to a DHCP server can eventually overflow a 32-bit ref…

Fix: after 4.3.6
Fix from $1,950 2019-01-16
Enterprise Linux Desktop MEDIUM 5.9
CVE-2017-3135EPSS 17%

Under some conditions when using both DNS64 and RPZ to rewrite query responses, query processing can resume in an inconsistent state leading to eithe…

Mitigation only
Fix from $1,600 2019-01-16
Enterprise Linux Desktop MEDIUM 5.9
CVE-2017-3136EPSS 11%

A query with a specific set of characteristics could cause a server using DNS64 to encounter an assertion failure and terminate. An attacker could de…

Fix: after 9.10.4
Fix from $1,600 2019-01-16
Enterprise Linux Desktop MEDIUM 5.9
CVE-2017-3143EPSS 18%

An attacker who is able to send and receive messages to an authoritative DNS server and who has knowledge of a valid TSIG key name for the zone and s…

Fix: after 9.11.1
Fix from $1,600 2019-01-16
Ceph MEDIUM 5.7
CVE-2018-14662

It was found Ceph versions before 13.2.4 that authenticated ceph users with read only permissions could steal dm-crypt encryption keys used in ceph d…

Fix: 13.2.4+
Fix from $1,600 2019-01-15
Ceph MEDIUM 6.5
CVE-2018-16846

It was found in Ceph versions before 13.2.4 that authenticated ceph RGW users can cause a denial of service against OMAPs holding bucket indices.

Fix: 13.2.4+
Fix from $1,600 2019-01-15
Enterprise Linux Desktop HIGH 8.1
CVE-2018-16886

etcd versions 3.2.x before 3.2.26 and 3.3.x before 3.3.11 are vulnerable to an improper authentication issue when role-based access control (RBAC) is…

Fix: 3.2.26 / 3.3.11+
Fix from $1,950 2019-01-14
Satellite MEDIUM 5.4
CVE-2018-16887

A cross-site scripting (XSS) flaw was found in the katello component of Satellite. An attacker with privilege to create/edit organizations and locati…

Fix: 3.9.0+
Fix from $1,600 2019-01-13
Enterprise Linux Desktop HIGH 7.8
CVE-2018-16865

An allocation of memory without limits, that could result in the stack clashing with another memory region, was discovered in systemd-journald when m…

Patch available
Fix from $1,950 2019-01-11
Enterprise Linux Desktop HIGH 7.8
CVE-2018-16864

An allocation of memory without limits, that could result in the stack clashing with another memory region, was discovered in systemd-journald when a…

Patch available
Fix from $1,950 2019-01-11
Modulemd CRITICAL 9.8
CVE-2017-1002157

modulemd 1.3.1 and earlier uses an unsafe function for processing externally provided data, leading to remote code execution.

Fix: after 1.3.1
Fix from $2,300 2019-01-10
Bodhi MEDIUM 6.1
CVE-2017-1002152

Bodhi 2.9.0 and lower is vulnerable to cross-site scripting resulting in code injection caused by incorrect validation of bug titles.

Fix: after 2.9.0
Fix from $1,600 2019-01-10
Openshift Container Platform HIGH 8.8
CVE-2019-0542

A remote code execution vulnerability exists in Xterm.js when the component mishandles special characters, aka "Xterm Remote Code Execution Vulnerabi…

Fix: 3.9.99 / 3.10.163+
Fix from $1,950 2019-01-09
Ansible MEDIUM 5.3
CVE-2018-16876

ansible before versions 2.5.14, 2.6.11, 2.7.5 is vulnerable to a information disclosure flaw in vvv+ mode with no_log on that can lead to leakage of …

Fix: 2.5.14 / 2.6.11+
Fix from $1,600 2019-01-03
Ansible Tower CRITICAL 9.8
CVE-2018-16879

Ansible Tower before version 3.3.3 does not set a secure channel as it is using the default insecure configuration channel settings for messaging cel…

Fix: 3.3.3+
Fix from $2,300 2019-01-03
Enterprise Linux Desktop HIGH 8.8
CVE-2018-5802

An error within the "kodak_radc_load_raw()" function (internal/dcraw_common.cpp) related to the "buf" variable in LibRaw versions prior to 0.18.7 can…

Fix: 0.18.7+
Fix from $1,950 2018-12-07
Enterprise Linux Desktop HIGH 8.8
CVE-2018-5805

A boundary error within the "quicktake_100_load_raw()" function (internal/dcraw_common.cpp) in LibRaw versions prior to 0.18.8 can be exploited to ca…

Fix: 0.18.8+
Fix from $1,950 2018-12-07
Enterprise Linux Desktop MEDIUM 6.5
CVE-2018-5800

An off-by-one error within the "LibRaw::kodak_ycbcr_load_raw()" function (internal/dcraw_common.cpp) in LibRaw versions prior to 0.18.7 can be exploi…

Fix: 0.18.7+
Fix from $1,600 2018-12-07
Enterprise Linux Desktop MEDIUM 6.5
CVE-2018-5801

An error within the "LibRaw::unpack()" function (src/libraw_cxx.cpp) in LibRaw versions prior to 0.18.7 can be exploited to trigger a NULL pointer de…

Fix: 0.18.7+
Fix from $1,600 2018-12-07
Enterprise Linux Desktop MEDIUM 6.5
CVE-2018-5806

An error within the "leaf_hdr_load_raw()" function (internal/dcraw_common.cpp) in LibRaw versions prior to 0.18.8 can be exploited to trigger a NULL …

Fix: 0.18.8+
Fix from $1,600 2018-12-07
Linux Desktop HIGH 7.5
CVE-2018-6101

A lack of host validation in DevTools in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to execute arbitrary code via a crafted HTML …

Fix: 66.0.3359.117+
Fix from $1,950 2018-12-04
Linux Desktop MEDIUM 6.5
CVE-2018-6095

Inappropriate dismissal of file picker on keyboard events in Blink in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to read local fi…

Fix: 66.0.3359.117+
Fix from $1,600 2018-12-04
Linux Desktop MEDIUM 6.5
CVE-2018-6098

Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to perform domain spoo…

Fix: 66.0.3359.117+
Fix from $1,600 2018-12-04
Linux Desktop MEDIUM 6.5
CVE-2018-6099

A lack of CORS checks in Blink in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to leak limited cross-origin data via a crafted HTML…

Fix: 66.0.3359.117+
Fix from $1,600 2018-12-04
Linux Desktop MEDIUM 6.5
CVE-2018-6103

A stagnant permission prompt in Prompts in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to bypass permission policy via a crafted H…

Fix: 66.0.3359.117+
Fix from $1,600 2018-12-04